PT-2026-90728 · Webassembly+3 · Wabt

CVE-2026-90648

·

Published

2026-09-12

·

Updated

2026-09-22

CVSS v4.0

7.1

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WebAssembly wabt versions prior to 1.0.42
Description An issue in wasm2c allows a sandbox escape, primarily on 32-bit platforms, through a method known as a table flip attack. The wasm rt allocate funcref table() function in wasm2c/wasm-rt-impl-tableops.inc fails to check the return value of calloc(). If the funcref table allocation fails, table->data remains NULL while table->size retains the guest-declared element count. Consequently, bounds checks are bypassed, and table element accesses resolve to absolute memory addresses. This enables arbitrary read and write access to host process memory and arbitrary code execution via table.get, table.set, and call indirect, compromising the isolation provided by wasm2c. This affects applications using wasm2c as a sandboxing boundary, such as RLBox and WasmBoxC, including Firefox's implementation for Graphite, Hunspell, Ogg, Expat, and Woff2 libraries. Exploitation typically requires allocation failure due to memory pressure, 32-bit host limitations, address-space limits (RLIMIT AS), or specific kernel settings like vm.overcommit memory=2.
Recommendations Update WebAssembly wabt to version 1.0.42 or later.

Exploit

Fix

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90648

Affected Products

Wabt